XOR and the cost of reusing a key
Break single-byte and repeating-key XOR, then recover both plaintexts from a reused one-time pad by crib dragging.
Assumes1. Recognising encodings
By the end you can
- Brute-force single-byte XOR and score candidates automatically
- Detect a repeating keysize using normalised Hamming distance
- Recover two plaintexts from a reused pad without ever learning the key
- Explain why key reuse destroys a cipher that is otherwise information-theoretically secure
- Recognise a stream cipher, a keystream generator and a hand-rolled 'custom' scheme as the same construction, and attack the keystream rather than the algorithm
1. Read
2. Use the tools
In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.
- XOR cipher decoder and key recovery
XOR text or hex against a key, brute-force single-byte XOR by English scoring, and recover repeating-key XOR by Hamming-distance keysize detection.
Open it in the workspace - XOR crib dragging for many-time pads
Recover both plaintexts when a one-time pad key is reused, by dragging a guessed word along the XOR of two ciphertexts.
Open it in the workspace - Hex to text converter
Convert hexadecimal to text and back, tolerating whitespace, commas, and `0x` prefixes. Runs entirely in your browser.
Open it in the workspace - Cipher identifier and automatic decoder
Paste anything and find out what it is. ctfpal runs every decoder and rotation, including multi-pass cascades, and ranks results by English-likeness and flag patterns.
Open it in the workspace - Recipe builder: chain decodes and transforms
Build a repeatable chain of operations - decode, decompress, XOR, decrypt - see the output after every step, and share the whole thing as a link.
Open it in the workspace
3. Try one now
Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.
4. Practise on the real thing
Real picoCTF challenges that use these techniques, easiest first. 27 match in total - see the full index.
Common mistakes
The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.
- Scoring candidates by 'looks like English' rather than by a character-frequency score, which makes the search unrepeatable and slow.
- Assuming the keysize with the lowest Hamming distance is right. Multiples of the true keysize score almost as well, and the smallest plausible one is usually the answer.
- Trying to recover the key from a two-time pad. You never need it: the XOR of the two ciphertexts is the XOR of the two plaintexts, and cribs go straight into that.
- Filtering single-byte candidates to printable output only. The right key often yields a plaintext carrying newlines, a length prefix or raw bytes, and a printable-only filter discards it before the score is ever read.
- Assuming the repeating key is a word. These challenges use raw bytes as often as text, and a search restricted to ASCII keys quietly excludes the answer while still returning a confident-looking ranking.
Checkpoint
Given two ciphertexts under one reused key, recover both plaintexts and describe each crib you used.
Teaching note
The space-XOR-letter trick is the moment this module lands. Show it before the general method: once students see that the XOR of two plaintexts leaks word boundaries for free, crib dragging stops feeling like magic.
Go deeper
The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.
Chapter 11, Implementing and Attacking Cryptography
Black Hat Go - Tom Steele, Chris Patten, and Dan Kottmann
Working stream-cipher code next to the attack on it, which is where key reuse stops being an abstraction.
Chapter 5, Cryptography
Designing Secure Software - Loren Kohnfelder
States the one-time pad's conditions plainly, so 'reused' reads as a broken precondition rather than bad luck.
Every book the curriculum cites has a page in the library.